Recital 140

Recital 140

Directive on the security of network and information systems · UE 2022/2555

(140)

The Commission should periodically review this Directive, after consulting stakeholders, in particular with a view to determining whether it is appropriate to propose amendments in light of changes to societal, political, technological or market conditions. As part of those reviews, the Commission should assess the relevance of the size of the entities concerned, and the sectors, subsectors and types of entity referred to in the annexes to this Directive for the functioning of the economy and society in relation to cybersecurity. The Commission should assess, inter alia, whether providers, falling within the scope of this Directive, that are designated as very large online platforms within the meaning of Article 33 of Regulation (EU) 2022/2065 of the European Parliament and of the Council (24) could be identified as essential entities under this Directive.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR formally designates essential and important operators and notifies each entity of its status, under the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025 transposing NIS 2). The ILR can revise its list at any time, independently of Commission reviews, as soon as an entity crosses a threshold or a sector is reclassified.

Luxgap practice: subscribe to ILR communications and the Memorial A, and have your qualification verified every 6 months, especially if you are growing or operating in digital infrastructure, cloud or managed ICT services in Luxembourg.